Back to All Modules

Appendices


#Contents

FileDescription
Tool Installation GuideInstalling and configuring essential pentesting tools on Kali/Parrot Linux
Methodology & MindsetThe pentest mindset, approach to unknown targets, and time management
GlossaryDefinitions of pentesting, AD, Windows, Linux, and web security terms
Machine-to-Technique IndexMap of HTB machines to the techniques they demonstrate

#How to Use These Appendices


#Tool Categories Quick Reference

CategoryPrimary Tools
Scanningnmap, masscan, rustscan, netexec
Web Enumerationgobuster, ffuf, feroxbuster, whatweb, wappalyzer
Web ExploitationBurp Suite, sqlmap, ysoserial, phpggc
AD EnumerationBloodHound (SharpHound/rusthound/bloodhound-python), windapsearch, ldapsearch
AD Exploitationimpacket suite, netexec, certipy, Rubeus, Mimikatz, bloodyAD
Password Attackshashcat, john, hydra, medusa
Lateral Movementimpacket (psexec/wmiexec/smbexec/atexec), evil-winrm
Tunnelingchisel, ligolo-ng, ssh, proxychains, socat
Linux PrivEsclinpeas, pspy, GTFOBins, linux-exploit-suggester
Windows PrivEscwinpeas, PowerUp, Seatbelt, PrintSpoofer, JuicyPotato, WES-NG
Credential DumpingMimikatz, procdump, secretsdump.py, LaZagne
Shellsmsfvenom, nishang, powercat, revshells.com